| Summary: |
test_shallow_submodules (bb.tests.fetch.GitShallowTest) failure because of git CVE fix |
| Product: |
[QA/Testing] Functional (self) Testing
|
Reporter: |
Alexandre Belloni <alexandre.belloni> |
| Component: |
bitbake-selftest | Assignee: |
Alexandre Belloni <alexandre.belloni> |
| Status: |
RESOLVED
FIXED
|
QA Contact: |
|
| Severity: |
normal
|
|
|
| Priority: |
High
|
CC: |
randy.macleod
|
| Version: |
unspecified | |
|
| Target Milestone: |
4.2 M1 | |
|
| Hardware: |
x86 | |
|
| OS: |
Multiple | |
|
| Whiteboard: |
backport all branches |
|
OS type for building Yocto:
|
---
|
Type of Regression:
|
---
|
|
Verified:
|
|
Documentation change:
|
No (bug/feature does not impact docs)
|
====================================================================== ERROR: test_shallow_submodules (bb.tests.fetch.GitShallowTest) ---------------------------------------------------------------------- Traceback (most recent call last): File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/tests/fetch.py", line 1872, in test_shallow_submodules self.git('submodule add file://%s' % smdir, cwd=self.srcdir) File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/tests/fetch.py", line 423, in git return bb.process.run(cmd, cwd=cwd)[0] File "/home/pokybuild/yocto-worker/oe-selftest-ubuntu/build/bitbake/lib/bb/process.py", line 189, in run raise ExecutionError(cmd, pipe.returncode, stdout, stderr) bb.process.ExecutionError: Execution of 'git submodule add file:///tmp/bitbake-fetch-hp5nq_8y/gitsubmodule' failed with exit code 128: Cloning into '/tmp/bitbake-fetch-hp5nq_8y/gitsource/gitsubmodule'... fatal: transport 'file' not allowed fatal: clone of 'file:///tmp/bitbake-fetch-hp5nq_8y/gitsubmodule' into submodule path '/tmp/bitbake-fetch-hp5nq_8y/gitsource/gitsubmodule' failed file:// transport is disabled in git until there is a fix for CVE-2022-39253. The first impacted host is ubuntu 22.04 but all distributions will probably follow: http://changelogs.ubuntu.com/changelogs/pool/main/g/git/git_2.34.1-1ubuntu1.5/changelog https://git.launchpad.net/ubuntu/+source/git/tree/debian/patches/CVE-2022-39253-1.patch?h=applied/ubuntu/jammy-security